Endpoint analysis release notes
The endpoint analysis (EPA) release note captures the enhancements, new features, fixed issues, and known issues in the EPA client for various platforms.
V26.7.1.15 for Windows (11 September 2026)
What’s new
-
Native ARM64 support for Endpoint Analysis on Windows
Endpoint Analysis now supports native installation on ARM64 Windows devices. The separate epasetup_ARM64.exe package is provided alongside the x64 client, eliminating the need to run the client through x64 emulation.
Deploy the package that matches the device architecture: epasetup.exe for x64 devices or epasetup_ARM64.exe for ARM64 devices. Native ARM64 support improves performance on ARM64 devices.
Limitations:
- Keylogger detection is not supported on ARM64.
- The ARM64 client requires a clean installation, so uninstall any existing Endpoint Analysis client before installing it.
[DPS-2775]
-
Keylogger detection in Endpoint Analysis (Preview)
Endpoint Analysis can now detect keylogging software running on an endpoint and report the detection details in Monitor for administrator visibility.
This feature helps administrators identify keylogging risks on managed endpoints. It is for visibility only and does not affect posture evaluation or access decisions. Enabling it cannot block users from accessing resources.
Note:
- This feature is currently in preview and is enabled per customer upon request.
- This feature is not supported on ARM64 devices.
[DPS-2737]
-
Bundled scan engine for Endpoint Analysis
The scan engine and its libraries are now included in the Endpoint Analysis client package and are installed together with the client. Packaging the client and scan engine as a single release ensures version alignment and removes the dependency on downloading scan engine components at runtime. The client application upgrade process remains unchanged.
[DPS-4580]
-
Endpoint Analysis is now 64-bit only
Endpoint Analysis is now available only as a 64-bit client. 32-bit (Win32/x86) binaries and installers are no longer produced or supported, and the installer does not run on 32-bit versions of Windows.
- Update any deployment scripts or software-distribution packages that reference a 32-bit Endpoint Analysis package.
- Both supported 64-bit architectures are available:
epasetup.exefor x64 devices andepasetup_ARM64.exefor ARM64 devices.
[DPS-2707]
-
Endpoint Analysis uses dedicated installation paths
Endpoint Analysis now installs in a product-specific folder and registry location instead of using the shared Secure Access Client location.
The installation paths are:
- Per-machine: C:\Program Files\Citrix\Secure Access Endpoint Analysis
- Per-user: %LocalAppData%\Citrix\Secure Access Endpoint Analysis
- Product registry key: HKLM\SOFTWARE\Citrix\Secure Access Endpoint Analysis
[DPS-5131]
-
Endpoint Analysis retention during uninstallation
Uninstalling a Citrix product no longer removes Endpoint Analysis when another installed Citrix product still depends on it. This applies when Endpoint Analysis is shared by multiple Citrix products on the same device, such as Citrix Workspace app, Citrix Enterprise Browser, and Citrix Secure Access. Previously, uninstalling one product can remove Endpoint Analysis and leave the other products without a posture client.
When an interactive uninstall would remove a still-needed client, the maintenance page lists the dependent applications that are keeping Endpoint Analysis installed.
Note:
- For scripted removal, a silent uninstall that correctly retains Endpoint Analysis returns exit code
1000. Configure1000as a success code in your deployment system. - To remove Endpoint Analysis despite the dependency, rerun the uninstall command from an elevated prompt with
/SkipConsumerCheck.
[DPS-5095]
- For scripted removal, a silent uninstall that correctly retains Endpoint Analysis returns exit code
-
Endpoint Analysis supports unattended deployment
Endpoint Analysis setup now supports unattended installation and uninstallation through software-distribution tools such as Configuration Manager and Intune. Use
/quietfor silent operations and/log <path>to specify the log location, on both installation and uninstallation.Note:
- These options are intended for centrally managed deployments. If the setup cannot write to the specified log path, it stops with exit code
1622instead of silently writing the log elsewhere. - During uninstallation, use the elevated-only
/SkipConsumerCheckoption to remove Endpoint Analysis even when another Citrix product depends on it. - Configure exit code
1000as a success code in your deployment tool. This code indicates that Endpoint Analysis was intentionally retained because another Citrix product still requires it.
[DPS-5493]
- These options are intended for centrally managed deployments. If the setup cannot write to the specified log path, it stops with exit code
-
Modernized Endpoint Analysis installer
The Endpoint Analysis installer interface is now enhanced for installation, repair, and maintenance. The enhanced interface appears when users interactively install, repair, or remove the client, such as from the downloads page or the maintenance page.
Note:
Silent and scripted deployments remain supported. As MSI-based deployment is no longer supported, use the following epasetup.exe command-line switches as needed.
-
/quiet, /silent, /q- Silent installation with no user interface. -
/passive- Displays progress only, with no interactive prompts. -
/uninstall- Uninstalls the product. -
/repair- Repairs an existing installation. -
/log "<file>"- Writes the installer log to the specified path. -
/norestart- Suppresses automatic restart after installation or uninstallation. -
/?, /h, /help- Displays installer help information.
[DPS-2645]
-
Fixed issues
-
Windows Update posture was reported from the wrong source: hot patched machines showed the age of a superseded baseline, patch ages were based on unrelated installations, and unmeasurable values were reported instead of being identified as unavailable.
[DPS-5465]
-
Posture signals from the third-party scanning engine are intermittently unavailable while the Windows Update service is starting.
[DPS-5379]
-
A scan-engine failure is reported as if no security product was installed on the device, making an engine fault indistinguishable from a genuinely unprotected device resulting in the same access denial.
[DPS-5121]
-
Signature verification now requires the signer to chain to a root certificate in the machine trust store. Roots trusted only in a per-user store are no longer accepted. Administrators using a custom trusted signing certificate must deploy it machine-wide.
[DPS-2038]
-
The
devicePostureNativeBridge.exeprocess can clear config.js, erasing saved connections. As a result, saved connections disappear from the client.[DPS-4701]
-
Repeated scans can cause memory and handle leaks.
[DPS-4552]
-
Users cannot retry an uninstall or remove a damaged installation.
With this fix, the maintenance page now offers the same deep-clean option as the silent path, allowing recovery when an uninstall fails on a damaged installation.
[DPS-3933]
-
Uninstalling Endpoint Analysis leaves behind an orphaned service registry key.
[DPS-5226]
-
The browser Endpoint Analysis flow fails when global server load balancing, HSTS, httpOnly cookies, and content security policy are all enabled on NetScaler Gateway.
[DPS-3684]
-
Users might remain indefinitely on the “Checking your device…” screen because large service responses can be truncated or over-read, preventing the device check from completing.
[DPSHELP-118]
-
The browser native-messaging host previously accepted connections from a process other than the verified browser because it checked only one end of the connection. With this fix, it now verifies that both ends belong to the same browser process.
[CTXBR-14824]
-
The clipboard handshake with the broker fails when the receiver process is closed.
[CTXBR-14570]
V26.6.1.4 for Windows (24 August 2026)
What’s new
-
Updated OPSWAT libraries that resolve memory leaks during device posture scans
The EPA client now includes updated OPSWAT (OESIS) libraries that resolve memory leaks during third-party product detection. Devices that perform frequent or continuous device posture scans no longer experience gradual memory buildup in the scanning process. The update also expands detection support for third-party security products, including ALYac, WatchGuard Endpoint Security Prime, and Trellix EDRF.
Fixed issues
-
Launching Citrix Secure Access from a browser might fail to load the home page when Full tunnel is selected on the Client Choices page. This issue occurs because EPA sends an incorrectly terminated HTTP header that is rejected by NetScaler Gateway.
[DPS-5100]
-
The device posture scan might not complete, leaving the client stuck on the “Checking your device…” message. This issue occurs when the scan configuration returned by the Device Posture service exceeds the client’s capacity, such as when an administrator enables a registry scan policy.
[DPS-4639]
-
Users might be denied access to resources during each scan cycle. This issue occurs when the local Device Posture admin service cannot consistently resolve the signed-in user while saving and reading context during periodic scans.
V26.5.1.7 for Windows (08 Jul 2026)
Fixed issues
-
On some devices, the EPA client incorrectly reports the Windows version. For example, a Windows 11 device was reported as an older Windows version, causing OS-based scan checks to evaluate incorrectly. This issue affects the EPA v1 (classic, on-premises) scan flow on certain Windows 10 and Windows 11 devices.
[DPS-3919]
-
In admin mode deployments, device certificate posture checks might fail because the EPA admin service does not automatically select a device certificate during evaluation. On affected setups, this causes periodic (continuous) device-certificate checks to fail repeatedly.
[DPSHELP-154]
-
For certain security products, such as CrowdStrike Falcon and OPSWAT-based products, scans do not correctly apply the Ignore Internet Check setting. As a result, checks such as virus-definition last-update time might fail even when the product is healthy.
This issue occurs in OPSWAT-based antivirus and definition scans for affected products.
[DPSHELP-153]
-
Users might experience device posture context read failures. For example, a browser extension might report that it cannot fetch device posture context because the stored EPA context file is not decrypted and read back reliably. This issue occurs when the Device Posture service writes and later re-reads encrypted posture context and periodic scan files.
[DPSHELP-144]
V26.03.31 for macOS (14 May 2026)
What’s new
-
Deprecation of independent library update
Starting with this release, runtime-dependent library updates are no longer supported. All future updates to these components will be delivered exclusively through new versions of the CitrixEndpointAnalysis application.
-
Static library integration with EPA appliaction
The core libraries required for system scanning are now bundled directly with the CitrixEndpointAnalysis application for both cloud and on-premises deployments.
This integration provides the following benefits:
- The integrated libraries now subjected to rigorous signature verification during application launch.
- By bundling these assets, the application no longer needs to download and extract libraries at runtime, resulting in faster initialization and more reliable startup.